mirror of
https://github.com/Kilo-Org/kilocode.git
synced 2026-08-30 17:14:40 +08:00
ef6b152ff8
* feat(worktree): add managed workspace cloning (#30117) * test(tui): skip crashing keymap textarea renderer * fix(core): allow skipping migration execution * fix(opencode): remove automatic full session diffs (#30127) * chore: generate * refactor(worktree): move project out of repository * zen: deepseek flash * fix(tui): remount session view on session switch (#30129) Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> * go: minimax m3 * refactor(opencode): inline local provider helpers (#30169) * refactor(opencode): simplify provider setup flow (#30173) * fix(app): show project sessions before path sync resolves (#30167) Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com> * fix(core): preserve session metadata migration identity (#30176) * refactor(session): align namespace imports and inline trivial helpers (#30180) * opencode(run): add queued prompt management (#30103) Direct run mode previously made submitted follow-up prompts irrevocable while a response was still running. Let users edit or remove queued prompts before dispatch without interrupting the active turn. * chore: generate * fix(acp): honor session/cancel by aborting the running turn (#30145) Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> * fix(tui): prevent prompt corruption when pasting near wide characters (#29710) Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> Co-authored-by: Simon Klee <hello@simonklee.dk> * fix(opencode): avoid nullable webfetch format schema (#30215) * chore: generate * fix(core): contain lsp warmup defects (#30226) * add run --replay mode (#30239) * chore: generate * chore: update nix node_modules hashes * fix(stats): restore leaderboard spacing * fix(stats): center top models dot grid * fix(stats): stabilize top models hover * fix(stats): align big-pickle provider resolution (#30274) * feat(app): v2 desktop UI improvements (#29689) Co-authored-by: Brendan Allan <git@brendonovich.dev> Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com> * chore: generate * fix(tui): clarify inline subagent rows (#30051) * fix(tui): handle events across workspaces (#30281) * feat(core): update Copilot for token-based billing (#30181) * fix(tui): keep background marker with subagent label (#30271) * fix(tui): keep retry attempt before message (#30275) * chore: generate * fix(opencode): enforce storage path invariants (#29666) * chore: generate * feat(core): add location-based permission service (#30287) * chore: generate * fix(tui): preserve live parts during session hydration (#30300) * fix(app): restore deferred MCP status updates (#30220) * fix: export v2 stylesheets and declare core node types (#30312) * chore: update nix node_modules hashes * fix(app): avoid suspending on pending child path (#30314) * fix(opencode): remove sunsetted gpt-5.2 and gpt-5.3-codex from allowed models for codex subscriptions (#30316) * chore: generate * feat(core): expose session location * chore: generate * fix(opencode): preserve websocket api errors (#30321) * refactor(core): simplify session pagination * feat(core): add location filesystem contract * feat(core): add dummy location filesystem layer * chore: generate * feat(opencode): add filesystem read and list routes * chore: generate * infra: stats * sync * feat(app): inset new layout session panels (#30342) * fix(app): tab title truncation and close button positioning (#30349) * tui: show model context in run footer (#30380) * tui: revert OpenTUI upgrade to 0.2.16 (#30383) * chore: update nix node_modules hashes * feat(core): add managed repository cache (#30408) * chore: generate * chore: generate * sync * feat(stats): add cache ratio section * feat(core): add flagged project references (#30414) * chore: generate * feat(core): support named migrations (#30418) * fix(stats): clean retired provider rows during sync (#30420) * fix(stats): mention opencode go in top models copy * feat(core): expose project reference filesystem access (#30423) * chore: generate * sync * fix(tui): scope diff viewer to session directory (#30426) * test: widen provider header timeout margin (#30427) * fix(plugin): restore private git install fallback (#30430) * fix(stats): remove leaderboard nav link * chore(opencode): remove scout agent (#30435) * chore: generate * feat(stats): improve cache ratio chart * chore: generate * fix(effect-drizzle-sqlite): preserve transaction begin errors (#30448) * chore: bump effect beta to 74 (#30449) * Revert "tui: revert OpenTUI upgrade to 0.2.16 (#30383)" (#30452) * chore: update nix node_modules hashes * refactor(opencode): improve startup time by 38% (#30453) Co-authored-by: starptech <starptech@starptechs-MBP.fritz.box> * chore: generate * fix(opencode): patch empty Gemini replay messages (#30463) * chore: generate * refactor(core): consolidate filesystem services (#30447) * chore: generate * run: enable interactive replay by default (#30465) * chore: update nix node_modules hashes * refactor(opencode): remove JSON storage migration (#30461) * chore: generate * chore: update nix node_modules hashes * fix(tui): stop idle background task spinner (#30484) * refactor(core): move v1 schemas into core (#30473) * chore: generate * fix: task id passed to background job for continuation (#30485) * chore: generate * feat(core): project copying and tracking directories (#30139) * chore: generate * fix(opencode): preserve signed thinking during anthropic reorder (#30182) * Revert "fix(opencode): preserve signed thinking during anthropic reorder" (#30502) * fix: rm tool reorder logic from old bug (#30483) * chore: generate * feat(app): polish home projects list UI (#30436) * feat(app): polish select-v2 component (#30446) Co-authored-by: Brendan Allan <git@brendonovich.dev> * fix(github): enforce existing git author identity (#30507) * feat(app): new update button (#30460) Co-authored-by: Brendan Allan <git@brendonovich.dev> * fix(opencode): fallback to sh for curl upgrade (#30499) Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> * fix(ui): render whole-file patches as complete diffs (#30516) * chore: generate * feat(app): add servers tab to settings dialog (#29675) * refactor(core): consolidate pty service (#30537) * chore: generate * tui: truncate sidebar file paths (#30531) * chore: update nix node_modules hashes * feat(stats): add geo breakdown (#30456) * chore: generate * chore: update nix node_modules hashes * fix(acp): classify apply_patch as edit (#30564) * fix(acp): classify task as think (#30565) * fix(acp): include external directory permission context (#30567) * fix(acp): clean read tool display content (#30569) * fix(tui): route question responses by session directory (#30578) * fix(stats): serve stats og image from banner * docs(go): add Qwen3.7 Plus model (#30594) * fix(openai): preserve websocket idle state (#30586) * refactor(core): remove ai sdk option fields (#30581) * chore: generate * test(core): cover v1 provider option lowering (#30599) * chore: generate * refactor(core): nest model api id (#30603) * fix(core): expose azure openai xhigh efforts (#30620) * feat(core): add skill registry and file agent loading (#30617) * chore: generate * chore: update nix node_modules hashes * fix(stats): count all go usage * chore: remove zed extension and automation (#30628) * fix(opencode): preserve variant for delegated tasks (#30630) * zen: update nvidia tos * fix(opencode): route SAP AI Core reasoning variants through modelParams (#30482) * chore: generate * fix(app): hide unavailable titlebar update (#30642) * feat(app): v2 thinking level selector (#30646) * fix(app,ui): session review reactivity and VCS query cache (#30660) * feat(core): add embedded v2 session runtime and tool foundation (#30632) * chore: generate * chore: update nix node_modules hashes * docs: correct compaction prune default (#30670) * fix(opencode): avoid shell cancel race (#30641) * feat: bump bedrock and add proper mantle support for openai models through aws bedrock (#30464) * test: wait for shell truncation readiness (#30679) * chore: update nix node_modules hashes * refactor(opencode): clean up task tool prompts (#30687) * feat(core): add command registry (#30624) * chore: generate * fix(acp): replay loaded session transcript (#30645) Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> * fix(core): reset pre-launch session projections (#30728) * feat(tui): improve experimental session switcher (#30738) * fix(opencode): respect disabled auto compaction on overflow (#30749) * zen: nemotron 3 ultra * fix(enterprise): install hono standard validator peer (#30740) Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> * fix build * chore: update nix node_modules hashes * make scripts executable * fix(tui): show toast when variant_list keybind used with no variants (#30724) * fix(opencode): `ACP.loadSession` should replay all messages (#30761) Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> * fix(opencode): attribute task child agent on creation (#30786) * fix(tui): add Vue syntax highlighting (#30802) * fix: bump @openrouter/ai-sdk-provider to 2.9.0 (#30800) * feat(core): moving sessions (#30640) * chore: generate * tweak: background agent prompting to avoid polling issues (#30790) * upgrade opentui to 0.3.2 (#30748) * chore: update nix node_modules hashes * feat(desktop): surface local server startup failures (#30822) * ci: publish * refactor(core): make v2 session inputs event sourced (#30785) * chore: generate * fix(llm): normalize OpenAI function tool schemas * chore: generate * feat(stats): refresh stats routes and homepage (#30419) * fix(stats): sort metric charts by top usage * feat(core): add public native API (#30828) * chore: generate * feat(app): color themes (#30824) Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com> * chore: generate * sync release versions for v1.16.0 * feat(core): attach global native tools (#30832) * chore: generate * feat(core): add Snowflake Cortex provider (#29901) Co-authored-by: Cortex Code <noreply@snowflake.com> * chore: generate * feat(core): persist v2 session context epochs (#30789) * chore: generate * feat(tui): allow backgrounding synchronous subagents (#30488) * fix(app): improve tab handling (#30669) * chore: generate * fix(tui): prioritize models slash autocomplete (#30848) * fix(tui): route permission replies to session directory (#30851) Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> * fix(cli): harden daemon lifecycle (#30844) * chore: generate * feat(app): improve desktop multi-server support (#30678) Co-authored-by: Brendan Allan <git@brendonovich.dev> * chore: generate * fix(app): handle tab overflow and scrolling in titlebar (#30886) * fix(app): tab overflow (#30894) * tui: guard path formatting inputs (#30469) Fixes #27726, #25216, #24856, #24294, #17071, #29164, #24837, #16865, #14279, #29895 * opencode/run: refresh themes after terminal reloads (#30917) * chore: generate * fix(tui): fall back to local cwd when editor spawns in attach mode (#30583) * docs: update Go Qwen tiered pricing (#30936) * chore: generate * feat(tui): add diff hunk navigation (#30935) * chore: rm fuzzy search on references (#30931) * fix: use mapError instead of orDie for context snapshot decoding (#30905) Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> * fix(core): recover corrupted models cache (#30947) * chore: bun install (#30968) * fix(opencode): resolve Bedrock hang by using node build conditions (#30873) * fix(workflows): retry nix-hashes compute-hash on transient failure (#30743) * fix(stats): scroll model charts to latest on mobile * fix(opencode): prevent destructive edit matches (#30932) * chore: generate * fix(core): respect v2 default agents (#30969) * chore: generate * test(opencode): remove disposal event wait race (#30971) * test(opencode): remove shell timeout output race (#30974) * fix(opencode): gate reasoning summaries by provider (#30973) * feat(core): admit v2 skill guidance (#30843) * fix(workflows): serialize desktop release uploads (#30978) * fix(stats): add mobile chart end spacing * release: v1.16.2 * refactor: kilo compat for v1.16.2 * fix(opencode): address v1.16.2 merge regressions * chore: update kilo-vscode visual regression baselines * fix(opencode): restore Kilo behavior after v1.16.2 merge * fix(opencode): retry Windows migration cleanup * test(opencode): restore clone and macOS watcher coverage * fix(opencode): address second-pass review for #12099 Preserve imported usage and retry partial JSON migrations. Refresh active dependency patches, remove the obsolete GCP patch, and regenerate Kilo HttpApi branding. --------- Co-authored-by: Dax <mail@thdxr.com> Co-authored-by: Dax Raad <d@ironbay.co> Co-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com> Co-authored-by: Frank <frank@anoma.ly> Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com> Co-authored-by: Aiden Cline <63023139+rekram1-node@users.noreply.github.com> Co-authored-by: Michael Hart <mhart@cloudflare.com> Co-authored-by: LukeParkerDev <10430890+Hona@users.noreply.github.com> Co-authored-by: Simon Klee <hello@simonklee.dk> Co-authored-by: smagnuso <smagnuso@gmail.com> Co-authored-by: Shoubhit Dash <shoubhit2005@gmail.com> Co-authored-by: Orca丶 <93272799+dauphinYan@users.noreply.github.com> Co-authored-by: Adam <2363879+adamdotdevin@users.noreply.github.com> Co-authored-by: Aarav Sareen <96787824+arvsrn@users.noreply.github.com> Co-authored-by: Brendan Allan <git@brendonovich.dev> Co-authored-by: Brendan Allan <14191578+Brendonovich@users.noreply.github.com> Co-authored-by: Kit Langton <kit.langton@gmail.com> Co-authored-by: James Long <longster@gmail.com> Co-authored-by: Dustin Deus <deusdustin@gmail.com> Co-authored-by: starptech <starptech@starptechs-MBP.fritz.box> Co-authored-by: Ulises Jeremias <ulisescf.24@gmail.com> Co-authored-by: Jack <jack@anoma.ly> Co-authored-by: Jérôme Benoit <jerome.benoit@sap.com> Co-authored-by: Ariane Emory <97994360+ariane-emory@users.noreply.github.com> Co-authored-by: LIU Xinyu <contact@lxy.cc> Co-authored-by: Colin McDonnell <colinmcd94@gmail.com> Co-authored-by: Sebastian <hasta84@gmail.com> Co-authored-by: opencode <opencode@sst.dev> Co-authored-by: Kamesh Sampath <kamesh.sampath@hotmail.com> Co-authored-by: Cortex Code <noreply@snowflake.com> Co-authored-by: pcadena-lila <pcadena@lila.ai> Co-authored-by: weiconghe <46336277+weiconghe@users.noreply.github.com> Co-authored-by: alberto <914199+alblez@users.noreply.github.com> Co-authored-by: kilo-maintainer[bot] <kilo-maintainer[bot]@users.noreply.github.com>
381 lines
13 KiB
TypeScript
381 lines
13 KiB
TypeScript
import { createHash } from "node:crypto"
|
|
import { describe, expect } from "bun:test"
|
|
import { Flag } from "@opencode-ai/core/flag/flag"
|
|
import * as Log from "@opencode-ai/core/util/log"
|
|
import { ConfigProvider, Effect, Layer } from "effect"
|
|
import {
|
|
HttpClient,
|
|
HttpClientRequest,
|
|
HttpClientResponse,
|
|
HttpRouter,
|
|
HttpServer,
|
|
HttpServerResponse,
|
|
} from "effect/unstable/http"
|
|
import { FSUtil } from "@opencode-ai/core/fs-util"
|
|
import { RuntimeFlags } from "../../src/effect/runtime-flags"
|
|
import { ServerAuth } from "../../src/server/auth"
|
|
import { authorizationRouterMiddleware } from "../../src/server/routes/instance/httpapi/middleware/authorization"
|
|
import { HttpApiApp } from "../../src/server/routes/instance/httpapi/server"
|
|
import { serveEmbeddedUIEffect, serveUIEffect } from "../../src/server/shared/ui"
|
|
import { testEffect } from "../lib/effect"
|
|
|
|
void Log.init({ print: false })
|
|
|
|
const testStateLayer = Layer.effectDiscard(
|
|
Effect.gen(function* () {
|
|
const original = {
|
|
KILO_SERVER_PASSWORD: Flag.KILO_SERVER_PASSWORD,
|
|
KILO_SERVER_USERNAME: Flag.KILO_SERVER_USERNAME,
|
|
envPassword: process.env.KILO_SERVER_PASSWORD,
|
|
envUsername: process.env.KILO_SERVER_USERNAME,
|
|
}
|
|
|
|
yield* Effect.addFinalizer(() =>
|
|
Effect.sync(() => {
|
|
Flag.KILO_SERVER_PASSWORD = original.KILO_SERVER_PASSWORD
|
|
Flag.KILO_SERVER_USERNAME = original.KILO_SERVER_USERNAME
|
|
restoreEnv("KILO_SERVER_PASSWORD", original.envPassword)
|
|
restoreEnv("KILO_SERVER_USERNAME", original.envUsername)
|
|
}),
|
|
)
|
|
}),
|
|
)
|
|
|
|
const it = testEffect(Layer.mergeAll(testStateLayer, FSUtil.defaultLayer, RuntimeFlags.layer()))
|
|
|
|
function restoreEnv(key: string, value: string | undefined) {
|
|
if (value === undefined) {
|
|
delete process.env[key]
|
|
return
|
|
}
|
|
process.env[key] = value
|
|
}
|
|
|
|
function app(input?: { password?: string; username?: string }) {
|
|
const handler = HttpRouter.toWebHandler(
|
|
HttpApiApp.routes.pipe(
|
|
Layer.provide(
|
|
ConfigProvider.layer(
|
|
ConfigProvider.fromUnknown({
|
|
KILO_SERVER_PASSWORD: input?.password,
|
|
KILO_SERVER_USERNAME: input?.username,
|
|
}),
|
|
),
|
|
),
|
|
),
|
|
{ disableLogger: true },
|
|
).handler
|
|
return {
|
|
request(input: string | URL | Request, init?: RequestInit) {
|
|
return Effect.promise(
|
|
(): Promise<Response> =>
|
|
Promise.resolve(
|
|
handler(
|
|
input instanceof Request ? input : new Request(new URL(input, "http://localhost"), init),
|
|
HttpApiApp.context,
|
|
),
|
|
),
|
|
)
|
|
},
|
|
}
|
|
}
|
|
|
|
function uiApp(input?: {
|
|
password?: string
|
|
username?: string
|
|
client?: Layer.Layer<HttpClient.HttpClient>
|
|
disableEmbeddedWebUi?: boolean
|
|
}) {
|
|
const handler = HttpRouter.toWebHandler(
|
|
HttpRouter.use((router) =>
|
|
Effect.gen(function* () {
|
|
const fs = yield* FSUtil.Service
|
|
const client = yield* HttpClient.HttpClient
|
|
const flags = yield* RuntimeFlags.Service
|
|
yield* router.add("*", "/*", (request) =>
|
|
serveUIEffect(request, { fs, client, disableEmbeddedWebUi: flags.disableEmbeddedWebUi }),
|
|
)
|
|
}),
|
|
).pipe(
|
|
Layer.provide(authorizationRouterMiddleware.layer.pipe(Layer.provide(ServerAuth.Config.defaultLayer))),
|
|
Layer.provide([
|
|
FSUtil.defaultLayer,
|
|
input?.client ?? httpClient(new Response("ui")),
|
|
RuntimeFlags.layer({ disableEmbeddedWebUi: input?.disableEmbeddedWebUi ?? false }),
|
|
HttpServer.layerServices,
|
|
ConfigProvider.layer(
|
|
ConfigProvider.fromUnknown({
|
|
KILO_SERVER_PASSWORD: input?.password,
|
|
KILO_SERVER_USERNAME: input?.username,
|
|
}),
|
|
),
|
|
]),
|
|
),
|
|
{ disableLogger: true },
|
|
).handler
|
|
return {
|
|
request(input: string | URL | Request, init?: RequestInit) {
|
|
return Effect.promise(
|
|
(): Promise<Response> =>
|
|
Promise.resolve(
|
|
handler(
|
|
input instanceof Request ? input : new Request(new URL(input, "http://localhost"), init),
|
|
HttpApiApp.context,
|
|
),
|
|
),
|
|
)
|
|
},
|
|
}
|
|
}
|
|
|
|
function routeOrderingApp() {
|
|
let proxiedUrl: string | undefined
|
|
const handler = HttpRouter.toWebHandler(
|
|
HttpRouter.use((router) =>
|
|
Effect.gen(function* () {
|
|
const fs = yield* FSUtil.Service
|
|
const client = yield* HttpClient.HttpClient
|
|
const flags = yield* RuntimeFlags.Service
|
|
yield* router.add("GET", "/session/:sessionID", () =>
|
|
Effect.succeed(HttpServerResponse.jsonUnsafe({ error: "Not Found" }, { status: 404 })),
|
|
)
|
|
yield* router.add("*", "/*", (request) =>
|
|
serveUIEffect(request, { fs, client, disableEmbeddedWebUi: flags.disableEmbeddedWebUi }),
|
|
)
|
|
}),
|
|
).pipe(
|
|
Layer.provide([
|
|
FSUtil.defaultLayer,
|
|
RuntimeFlags.layer({ disableEmbeddedWebUi: true }),
|
|
httpClient(new Response("ui"), (request) => {
|
|
proxiedUrl = request.url
|
|
}),
|
|
HttpServer.layerServices,
|
|
]),
|
|
),
|
|
{ disableLogger: true },
|
|
).handler
|
|
return {
|
|
proxiedUrl: () => proxiedUrl,
|
|
request(input: string | URL | Request, init?: RequestInit) {
|
|
return Effect.promise(
|
|
(): Promise<Response> =>
|
|
Promise.resolve(
|
|
handler(
|
|
input instanceof Request ? input : new Request(new URL(input, "http://localhost"), init),
|
|
HttpApiApp.context,
|
|
),
|
|
),
|
|
)
|
|
},
|
|
}
|
|
}
|
|
|
|
function httpClient(response: Response, onRequest?: (request: HttpClientRequest.HttpClientRequest) => void) {
|
|
return Layer.succeed(
|
|
HttpClient.HttpClient,
|
|
HttpClient.make((request) => {
|
|
onRequest?.(request)
|
|
return Effect.succeed(HttpClientResponse.fromWeb(request, response))
|
|
}),
|
|
)
|
|
}
|
|
|
|
function responseText(response: Response) {
|
|
return Effect.promise(() => response.text())
|
|
}
|
|
|
|
describe("HttpApi UI fallback", () => {
|
|
// kilocode_change start - embedded UI is the only supported fallback; never proxy to app.opencode.ai
|
|
it.live("returns not found without proxying when embedded UI is disabled", () =>
|
|
Effect.gen(function* () {
|
|
let proxied = false
|
|
const response = yield* uiApp({
|
|
disableEmbeddedWebUi: true,
|
|
client: httpClient(new Response("ui"), () => {
|
|
proxied = true
|
|
}),
|
|
}).request("/")
|
|
|
|
expect(response.status).toBe(404)
|
|
expect(yield* Effect.promise(() => response.json())).toEqual({ error: "Not Found" })
|
|
expect(proxied).toBe(false)
|
|
}),
|
|
)
|
|
// kilocode_change end
|
|
|
|
it.live("serves embedded UI assets when Bun can read them but access reports missing", () =>
|
|
Effect.gen(function* () {
|
|
let readPath: string | undefined
|
|
|
|
const fs = yield* FSUtil.Service
|
|
const response = yield* serveEmbeddedUIEffect(
|
|
"/assets/app.js",
|
|
{
|
|
...fs,
|
|
existsSafe: () => Effect.die("embedded UI should not rely on filesystem access checks"),
|
|
readFile: (path) => {
|
|
readPath = path
|
|
return path === "/$bunfs/root/assets/app.js"
|
|
? Effect.succeed(new TextEncoder().encode("console.log('embedded')"))
|
|
: Effect.die(`unexpected embedded UI path: ${path}`)
|
|
},
|
|
},
|
|
{ "assets/app.js": "/$bunfs/root/assets/app.js" },
|
|
).pipe(Effect.map(HttpServerResponse.toWeb))
|
|
|
|
expect(response.status).toBe(200)
|
|
expect(readPath).toBe("/$bunfs/root/assets/app.js")
|
|
expect(response.headers.get("content-type")).toContain("text/javascript")
|
|
expect(yield* responseText(response)).toBe("console.log('embedded')")
|
|
}),
|
|
)
|
|
|
|
it.live("allows embedded UI terminal wasm and theme preload CSP", () =>
|
|
Effect.gen(function* () {
|
|
const script = 'document.documentElement.dataset.theme = "dark"'
|
|
|
|
const fs = yield* FSUtil.Service
|
|
const response = yield* serveEmbeddedUIEffect(
|
|
"/",
|
|
{
|
|
...fs,
|
|
readFile: (path) => {
|
|
return path === "/$bunfs/root/index.html"
|
|
? Effect.succeed(
|
|
new TextEncoder().encode(
|
|
`<html><head><script id="oc-theme-preload-script">${script}</script></head></html>`,
|
|
),
|
|
)
|
|
: Effect.die(`unexpected embedded UI path: ${path}`)
|
|
},
|
|
},
|
|
{ "index.html": "/$bunfs/root/index.html" },
|
|
).pipe(Effect.map(HttpServerResponse.toWeb))
|
|
|
|
const csp = response.headers.get("content-security-policy") ?? ""
|
|
expect(csp).toContain("script-src 'self' 'wasm-unsafe-eval'")
|
|
expect(csp).toContain(`'sha256-${createHash("sha256").update(script).digest("base64")}'`)
|
|
expect(csp).toContain("connect-src * data:")
|
|
}),
|
|
)
|
|
|
|
it.live("keeps matched API routes ahead of the UI fallback", () =>
|
|
Effect.gen(function* () {
|
|
const server = routeOrderingApp()
|
|
const response = yield* server.request("/session/ses_nope")
|
|
|
|
expect(response.status).toBe(404)
|
|
expect(server.proxiedUrl()).toBeUndefined()
|
|
}),
|
|
)
|
|
|
|
it.live("requires server password for the web UI", () =>
|
|
Effect.gen(function* () {
|
|
const response = yield* uiApp({
|
|
password: "secret",
|
|
username: "kilo", // kilocode_change
|
|
disableEmbeddedWebUi: true,
|
|
}).request("/")
|
|
|
|
expect(response.status).toBe(401)
|
|
expect(response.headers.get("www-authenticate")).toBe('Basic realm="Secure Area"')
|
|
}),
|
|
)
|
|
|
|
it.live("accepts auth token for the web UI", () =>
|
|
Effect.gen(function* () {
|
|
let proxied = false // kilocode_change
|
|
const response = yield* uiApp({
|
|
password: "secret",
|
|
username: "kilo", // kilocode_change
|
|
disableEmbeddedWebUi: true,
|
|
// kilocode_change start - authenticated requests still must not proxy when embedded UI is disabled
|
|
client: httpClient(new Response("<html>kilo</html>", { headers: { "content-type": "text/html" } }), () => {
|
|
proxied = true
|
|
}),
|
|
// kilocode_change end
|
|
}).request(`/?auth_token=${btoa("kilo:secret")}`)
|
|
|
|
// kilocode_change start
|
|
expect(response.status).toBe(404)
|
|
expect(yield* Effect.promise(() => response.json())).toEqual({ error: "Not Found" })
|
|
expect(proxied).toBe(false)
|
|
// kilocode_change end
|
|
}),
|
|
)
|
|
|
|
it.live("accepts basic auth for the web UI", () =>
|
|
Effect.gen(function* () {
|
|
let proxied = false // kilocode_change
|
|
const response = yield* uiApp({
|
|
password: "secret",
|
|
username: "kilo", // kilocode_change
|
|
disableEmbeddedWebUi: true,
|
|
// kilocode_change start
|
|
client: httpClient(new Response("ui"), () => {
|
|
proxied = true
|
|
}),
|
|
// kilocode_change end
|
|
}).request("/", {
|
|
headers: { authorization: `Basic ${btoa("kilo:secret")}` },
|
|
})
|
|
|
|
// kilocode_change start
|
|
expect(response.status).toBe(404)
|
|
expect(yield* Effect.promise(() => response.json())).toEqual({ error: "Not Found" })
|
|
expect(proxied).toBe(false)
|
|
// kilocode_change end
|
|
}),
|
|
)
|
|
|
|
it.live("accepts basic auth passwords containing colons for the web UI", () =>
|
|
Effect.gen(function* () {
|
|
const response = yield* uiApp({
|
|
password: "sec:ret",
|
|
username: "opencode",
|
|
disableEmbeddedWebUi: true,
|
|
}).request("/", {
|
|
headers: { authorization: `Basic ${btoa("opencode:sec:ret")}` },
|
|
})
|
|
|
|
expect(response.status).toBe(404) // kilocode_change - auth succeeds, but Kilo does not proxy a fallback UI
|
|
}),
|
|
)
|
|
|
|
// Regression for #25698 (Ope): the browser fetches the PWA manifest and
|
|
// its icons via flows that don't carry app-managed credentials (the
|
|
// `<link rel="manifest">` request is not under page-auth control), so the
|
|
// server returning 401 breaks PWA install. These specific public assets
|
|
// should bypass auth.
|
|
it.live("serves the PWA manifest without auth even when a server password is set", () =>
|
|
Effect.gen(function* () {
|
|
for (const path of ["/site.webmanifest", "/web-app-manifest-192x192.png", "/web-app-manifest-512x512.png"]) {
|
|
const response = yield* uiApp({
|
|
password: "secret",
|
|
username: "kilo", // kilocode_change
|
|
disableEmbeddedWebUi: true,
|
|
client: httpClient(new Response("ok")),
|
|
}).request(path)
|
|
expect(response.status).not.toBe(401)
|
|
}
|
|
}),
|
|
)
|
|
|
|
it.live("allows web UI preflight without auth", () =>
|
|
Effect.gen(function* () {
|
|
const response = yield* app({ password: "secret", username: "kilo" }).request("/", {
|
|
// kilocode_change
|
|
method: "OPTIONS",
|
|
headers: {
|
|
origin: "http://localhost:3000",
|
|
"access-control-request-method": "GET",
|
|
},
|
|
})
|
|
|
|
expect(response.status).toBe(204)
|
|
expect(response.headers.get("access-control-allow-origin")).toBe("http://localhost:3000")
|
|
}),
|
|
)
|
|
})
|